Home Bundles Device Hardening: SSH, AAA & Secure Access SSH Hardening to Version 2 Advanced Published 2026-07-04
SSH Hardening to Version 2 Bundle lab · $29.99
Harden the management-plane SSH service on a single Cisco IOS router so only SSHv2 is permitted and session limits are tightened. The baseline lab already has working SSH. You will enforce SSH version 2, set a 60-second authentication timeout, and limit authentication retries to 2. You will also regenerate a 2048-bit RSA key (an exec-only step) and validate with show commands.
Learning objectives Enforce SSHv2-only access on Cisco IOS (ip ssh version 2) Tighten SSH session parameters (authentication timeout and retries) Regenerate a 2048-bit RSA host key from exec mode Verify SSH state and parameters with show ip ssh Explain why SSHv2 and 2048-bit keys mitigate weaknesses of SSHv1 and short moduli Troubleshooting focus If show ip ssh is empty or disabled, confirm an RSA key exists and VTY permits SSH RSA key generation fails without both a non-default hostname and ip domain-name If SSH sessions hang, check ip ssh time-out and authentication-retries values Ensure line vty uses transport input ssh and a working login method (login local or AAA) What's included in the package Work / baseline CML import — lab-work.yaml Topology diagram — topology.svg Print-ready topology diagram (PDF) — topology.pdf Step-by-step learner guide (Markdown — for Obsidian/VS Code) — lab-guide.md Branded PDF lab guide — open in any viewer (Adobe/Preview) — lab-guide.pdf Getting-started README — README.md Verification checklist — verification-checklist.md How this lab is graded Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with access-class, are stated in the guide and do have to match.Addresses, modes and protocol keywords are exact. An IP address, a subnet mask, switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide.Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found. Download access New here? See how the download → build in CML → grade loop works.
This lab is part of the Device Hardening: SSH, AAA & Secure Access bundle — own every lab in it permanently for a one-time $29.99.
Create a free account, then own the Device Hardening: SSH, AAA & Secure Access bundle for a one-time $29.99 — buy once, keep every lab forever.
Found a problem with this lab? Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.